So consider a situation where someone receives a password in plain text, and the password never expires and never gets changed by the user.
All things considered, a token is a token, so whether the "password" is sent in plaintext, or whether a nonce hex key is provided by e-mail, anything sent by e-mail should have a shelf life, even if it's a relatively long one of like 30 days.
Ideally, it should expire in hours or minutes. If they don't get around to it fast enough, you have the user's e-mail, just tell them you need to send them another, because the last one expired. That way, you're forcing a live user to interact with the system, and act quickly, to establish proper authentication credentials.
Welcome to our credit tool, Travel Bank, which allows customers to manage their credits with JetBlue. An account has been created for you with the account number and username below. You can view your transactions by clicking Here. For your security, your password has been sent in a separate email.
Travel Bank Account Number: xxxxxxxxxxxxxxx
Username: xxxxxxxxxxxxxxx
As a TrueBlue member, you can easily manage this account, including updating your password, when you sign in to TrueBlue. (Not a member yet? Register here).
To book a flight using your Travel Bank credit, visit jetblue.com and choose Travel Bank as your form of payment.
If you are a CompanyBlue Administrator, your travelers will log into your CompanyBlue account and book normally. Once Travel Bank access is granted to the appropriate travelers, they will be able to use it as a form of payment in the booking flow. For more details, refer to your CompanyBlue training materials.
We hope you find Travel Bank a useful tool for managing your credits. If you require further assistance, please visit the help section of our website.
Sincerely,
"